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Abstract 

This work is about changing action domain descriptions 
in dynamic logic. We here revisit the semantics of ac- 
tion theory contraction, giving more robust operators 
that express minimal change based on a notion of dis- 
tance between models. We then define syntactical con- 
traction operators and establish their correctness w.r.t. 
our semantics. Finally we show that our operators sat- 
isfy the PDL-counterpart of the standard postulates for 
theory change adopted in the literature. 

Introduction and Motivation 

Let an intelligent agent be designed to perform rationally 
in a dynamic world, and suppose she should reason about 
the dynamics of an automatic coffee machine. Suppose that 
the agent believes that a coffee is a hot beverage. Now 
suppose that some day she gets a coffee and observes it is 
cold. In such a case, the agent must change her beliefs 
about the relationship between the propositions "I have a 
coffee" and "I have a hot beverage". This example is an 
instance of the problem of changing propositional belief 
bases and is largely addressed in the literature about belief 
change (Gardenfors 1988) and belief update (Katsuno and 
Mendelzon 1992). 

Next, let our agent believe that whenever buying a coffee 
on the machine, she gets a hot beverage. This means that in 
every state of the world that follows the execution of buying, 
the agent possesses a hot beverage. Some day, it may hap- 
pen that the machine is running out of cups, and then after 
buying, the coffee runs through the shelf and so the agent 
holds no hot beverage. 

Imagine now the agent believes that if she has a token, 
then it is always possible to buy coffee. However, during a 
blackout, even with a token the agent does not manage to 
order her coffee on the machine. 

The last two examples illustrate situations where chang- 
ing the beliefs about the behavior of the action of buying 
coffee is mandatory. In the first one, buying coffee, once 
believed to be deterministic, has now to be seen as nonde- 
terministic, or alternatively to have a different outcome in a 
more specific context (e.g. if there is no cup in the machine). 
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In the second example, the executability of the action under 
concern is questioned in the light of new information show- 
ing a context that was not known to preclude its execution. 

Such cases of theory change are very important in logical 
descriptions of dynamic domains: it may always happen that 
one discovers that an action actually has a behavior that is 
different from that one has always believed it had. 

Up to now, theory change has been studied mainly for 
knowledge bases in classical logics, both in terms of revision 
and update. Since (Fuhrmann 1989), only in a few recent 
works it has been considered in the realm of modal logics, 
viz. in epistemic logic (Hansson 1999) and in dynamic log- 
ics (Herzig, Perrussel, and Varzinczak 2006), and in action 
languages (Eiter et al. 2005). Some other works (Shapiro 
et al. 2000; Jin and Thielscher 2005) have investigated re- 
vision of beliefs about facts of the world. In our scenario, 
this would concern for example the truth of token in a given 
state: the agent believes she has a token, but is wrong about 
that and might subsequently be forced to revise her beliefs 
about the current state of affairs. Such belief revision opera- 
tions do not modify the agent's beliefs about the action laws. 
In opposition to that, here we are interested exactly in such 
modifications. 

Logical Preliminaries 

Our base formalism is Propositional Dynamic Logic (PDL) 
without the * operator (Harel, Tiuryn, and Kozen 2000). 

Action Theories in Dynamic Logic 

Let 2lct = {ai,a2, . . .} be the set of atomic actions of a 
given domain. An example of atomic action is buy. To each 
action a there is associated a modal operator [a], ^cop = 
{Pi,P2i ■ • ■} denotes the set of propositional constants, also 
called fluents or atoms. Examples of those are token ("the 
agent has a token") and coffee ("the agent holds a coffee"). 
The set of all literals is £it = {li, £2, . ■ .}, where each ii 
is either /7 or -ip, for some;? G ^cop. If ^ = -ip, then we 
identify ->£ with p. By \£\ we denote the atom in £. 

We use if, ip, ... to denote Boolean formulas, an example 
of which is coffee —> hot. S'trtl is the set of all Boolean for- 
mulas. A propositional valuation v is a maximally consistent 
set of literals. We denote by v Ih (/? the fact that v satisfies (p. 
By val{ip) we denote the set of all valuations satisfying ip. 



|=p. is the classical consequence relation. Cn{ip) denotes all 
logical consequences of ip in classical propositional logic. 

With IP{^) we denote the set of prime impUcants (Quine 
1952) of if. By n we denote a prime implicant, and atm^n) 
is the set of atoms occurring in it. For given ( and tt, i £ n 
abbreviates 'I is a literal of tt' . 

We will use <P, !Z/, . . . to denote complex formulas (formu- 
las with modal operators). An example of a complex for- 
mula is -icojfee —>■ [buy\coffee. (a) is the dual operator of 
[a] ((a)<?=def -[«]-<?). 

A PDL-model is a tuple ./# = {W,R) where W is a set 
of valuations, and R maps action constants a to accessibility 

relations R„ C W x W. Given ^, 1= p ip is, true at world 

w of model ^) if w \\- p; \= \a\(l> if 1= ^ for every w' s.t. 
{w, w') £ Ra', truth conditions for the other connectives are 
as usual. By Ai we will denote a set of PDL-models. 

^ is a model of (Z* (noted 1= <?) if and only if 1= <Z'forall 
w £ W. ./^ is a model of a set of formulas S (noted |= E) 

if and only if |= fp for every ^ G S. ^Z* is a consequence of 
the global axioms S in all PDL-models (noted E |= ^) if 

and only if for every ^ , if |= S, then |= (p. 

With PDL we can state laws describing the behavior of 
actions. Following the tradition in the reasoning about ac- 
tions community, we here distinguish three types of them. 

Static Laws A static law is a formula ip G ^ttiI. It is a 
formula that characterizes the possible states of the world. 
An example of static law is coffee —^ hot: if the agent holds 
a coffee, then she holds a hot beverage. The set of all static 
laws of a domain is denoted by S . 

Effect Laws An effect law for a is of the form (f — > [a]ip, 
where </?, t/; G Jml. Effect laws are formulas relating an ac- 
tion to its effects, which can be conditional. The consequent 
^p is the effect that always obtains when a is executed in a 
state where the antecedent ip holds. If a is a nondeterminis- 
tic action, then ip is typically a disjunction. An example of 
such a law is token — > [buy\hot: whenever the agent has a 
token, after buying, she has a hot beverage. If tp is incon- 
sistent we have a special kind of effect law that we call an 
inexecutability law. For example, -itoken —>■ [buy\l. says 
that buy cannot be executed if the agent has no token. The 
set of effect laws of a domain is denoted by £ . 

Executability Laws An executability law for a has the form 
if — > (a)T, with ip G Jrnl. It stipulates the context in which 
a is guaranteed to be executable. (In PDL, the operator {a) 
is used to express executability, (a)T thus reads "a's execu- 
tion is possible".) For instance, token — > {buy)T says that 
buying can be executed whenever the agent has a token. The 
set of all executability laws of a domain is denoted by X . 

Given a, E^ (resp. X^) will denote the set of only those 
effect (resp. executability) laws about a. 

Action Tlieories T=iSU£UA'isan action theory. 



For the sake of clarity, we will here abstract from the 
frame problem (McCarthy and Hayes 1969) and the rami- 
fication problem (Finger 1987), and assume that the agent's 
theory contains all frame axioms (cf. (Herzig, Perrussel, and 
Varzinczak 2006) for a contraction approach within a solu- 
tion to the frame problem). The action theory of our example 
will be: 



T = 



coffee — > hot, token — > {buy)T , 

-^coffee — > [buy\coffee, token —* [buy\-^token, 

-'token —>■ [buy]J-, -itoken — > [buyj-itoken, 

coffee — i- [buy]coffee,hot — > [buy]hot 




Figure 1 below shows a PDL-model for the theory T. 

Figure 1: A model for the coffee machine scenario, b, t, c, 
and h stand for, respectively, buy, token, coffee, and hot. 

Sometimes it will be useful to consider models whose 
possible worlds are all the possible worlds allowed by S: 

Definition 1 Let T=SU£UXbean action theory. Then 
^ = (W, R) is the big model of T if and only if: 

• W = val{S); and 

• Ra= {{w, w') : \/.ip -^ [a]t/> e £,, if \^ <p then ^^, 0}. 

Figure 2 below depicts the big model of T. 
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Figure 2: The big model for the coffee machine scenario. 

Elementary Atoms 

Given ip G 5ni[, E{ip) denotes the elementary atoms actu- 
ally occurring in ip. For example, E{-^pi A {-^Pi "^ P2)) = 
{PitPt}- An atom/? is e55e«?/a/ to (y9 if andonly if/? G E{p') 
for all ip' such that |= ip •*-*■ ip' . For instance, /7]^ is essential 
to -ipi A {-ipi V/)2). E!{ip) will denote the essential atoms of 
ip. (If ip\s a, tautology or a contradiction, then E!{ip) = 0.) 

For ip G 5m t, tp* is the set of all ip' G ^va[ such that 
(p \= ip' and E{ip') C E!{ip). For instance, Pi V P2 ^ 



Pi*' as Pi hp.Pi V P2 but£(/Ji V p^) 2 E.'ip^). Clearly, 



E{/\ip*) = E!{/\(p*). Moreover, whenever |= ip 
then E!{ip) = E!{ip') and also ip* = if'*. 



V' 



Theorem 1 (Least atom-set theorem (Parikh 1999)) 

|=p. cp ^^ /\ ip*, and E{ip*) C E{ip') for every ip' s.t. 

Thus for every ^p G IJrfil there is a unique least set of 
elementary atoms such that ip may equivalently be expressed 
using only atoms from that set' Hence, Cn(ip) = Cn{ip*). 

Prime Valuations 

Given a valuation v, v' C v is a subvaluation. For W a set 
of valuations, a subvaluation v' satisfies ip G ^iril modulo W 
(noted v' lb, ip) M and only if v Ih ip for all v G W such that 
v' C V. A subvaluation v essentially satisfies ip modulo W 
(v Ih' (/3) if and only if V 1^ <y9and{|^| : i e v} QE!{ip). 

Deflnition 2 Let ip G i?m[ one/ W fee a set of valuations. A 
subvaluation v is a prime subvaluation of ip (modulo W) if 

and only ifv Ih ip and there is no v C v s.t. v Ih ip. 

A prime subvaluation of a formula ip is one of the weakest 
states of truth in which ip is true. (Notice the similarity with 
the syntactical notion of prime implicant (Quine 1952).) 

By base{ip, W) we denote the set of all prime subvalua- 
tions of ip modulo W. 

Theorem 2 Letip G ^ml and W be a set of valuations. Then 
for all w eW,w W-ipifandonlyifw Ih \/,^hase(ip,w) Kev^- 

Closeness Between Models 

When contracting a formula from a model, we will perform 
a change in its structure. Because there can be several differ- 
ent ways of modifying a model (not all of them minimal), we 
need a notion of distance between models to identify those 
that are closest to the original one. 

As we are going to see in more depth in the sequel, chang- 
ing a model amounts to modifying its possible worlds or 
its accessibility relation. Hence, the distance between two 
PDL-models will depend upon the distance between their 
sets of worlds and accessibility relations. These here will be 
based on the symmetric difference between sets, defined as 
X-Y = {X\Y)\J{Y\X). 

Definition 3 Let .£ = {W,R) be a model. J(' = {W',R') 
is as close to .^ as M" = {W" ,R"), noted J(' -<j( M" , 
if and only if 

• either W-W' C W-W" 

• or W-W' = W-W" andR-R' C R-R" 

(Notice that other distance notions are also possible, like 
e.g. considering the cardinality of symmetric differences.) 



Semantics of Contraction 

When contracting a law <Z> we must ensure that <!> becomes 
invalid in at least one (possibly new) model of the dynamic 
domain. Because there can be lots of models to consider, 
we start with a set M. of models in which <!> is (potentially) 
valid. Thus contracting <P amounts to make it no longer valid 
in this set of models. What are the operations that must be 
carried out to achieve that? Throwing models out of M. does 
not work, since <!> will keep on being valid in all models of 
the remaining set. Thus we should add new models to M.. 
Which models? Well, models in which <1> is not true. But 
not any of such models: taking models falsifying <1> that are 
too different from our original models will certainly violate 
minimal change. 

Hence, we shall take some model .-^ G A^ as basis and 
manipulate it to get a new model ./£' in which <1> is not true. 
In P D L, the removal of a law ^ from a model y^ amounts to 
modifying the possible worlds or the accessibility relation in 
^ so that <!> becomes false. Such an operation gives as re- 
sult a set .M^ of models, each of which is no longer a model 
of <^. But if there are several candidates, which ones should 
we choose? We shall take those that are minimal modifica- 
tions of the original yM . Note that there can be more than 
one .M' that is minimal. Because adding just one of these 
new models is enough to invalidate ^, we take all possible 
combinations M. U {^'} of expanding our set of models by 
one minimal model. The result will be a set of sets of models. 
In each set of models there will be one ^' falsifying <1>. 

Contraction of Executability Laws 

Intuitively, to contract an executability law ip ^* (^) T in one 
model, we remove arrows leaving iy9-worlds. To success the 
operation, we have to guarantee that in the resulting model 
there is at least one (/j-world with no departing a-arrow. 

Definition 4 Let ^ = (W,R) be a PDL-model. Then 
^' = {W',R') G J^^^u\-j if and only if 

• W = W 

• R' CR 

• If{w, w') eR\ R', then \^ ip 

• There is w ^ V/ s.t. ^ 'P ^' («)T 

w 

To get minimal change, we want such an operation to be 
minimal w.r.t. the original model: we should remove a min- 
imum set of arrows sufficient to get the desired result. 

Definitions Let ./£ be a PDL-model and ip — > (a)T an 
executability law. Then 



contraction 



{Ji.ip-^ (a)T) = |Jmin{.4'^^^^,^^,r<.^} 



And now we define the sets of possible models resulting 
from the contraction of an executability in a set of models: 

Definition 6 Let M. be a set of models, and ip ^ (<2)T an 



'The dual notion (redundant atoms) is also addressed in the lit- 
erature, e.g. in (Herzig and Rifi 1999), with similar purposes. 



executability law. Then Ai 



ip^(a)T 



= {M' : M' = M\J 



{J('^,J(' G contraction^../^ ,ip -^ (a)T),^ G M\. 



In our example, consider A4 = {./#}, where ./# is the 
model in Figure 2. When the agent discovers that even with 
a token she does not manage to buy a coffee anymore, she 
has to change her models in order to admit models with 
states where token is the case but from which there is no 
fcMy-transition at all. Because having just one of such worlds 
in each new model is enough, taking those resulting models 
whose accessibility relations are maximal guarantees mini- 
mal change. Hence we get X^t^,,^ (,,„,,) y = {-^ U i-^/} : 
1 < i < 3}, where each .^/ is depicted in Figure 3. 
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Figure 3: Models resulting from contracting the executabil- 
ity law token — > {biiy)T in the model ./^ of Figure 2. 



Contraction of Effect Laws 

When the agent discovers that there may be cases when after 
buying she gets no hot beverage, she must give up the law 
token — i- [buy\hot in her models. This means that token A 
{buy)-ihot shall now be admitted in at least one world of 
some of her new models of beliefs. Hence, to contract an 
effect law tp — > [a]tp from a given model, we have to put 
new arrows leaving i^-worlds to worlds satisfying -iip. 

In our example, when contracting token —>■ [buy\hot in 
the model of Figure 2, we add arrows from tofew-worlds 
to -i/zo?-worlds. The challenge in such an operation is in 
guaranteeing minimal change: because coffee — > hot, and 
then -ihot —f -^coffee, this should also give {buy)-icoffee 



(-icoffee is relevant to -ihot). Hence, we can add arrows 
from fofew-worlds to -i/zof A -^coffee A tofen-worlds, as well 
as to -ihot A -icoffee A -itoken (Figure 4). Pointing the ar- 
row to -ihot A -icoffee A token would make us lose the ef- 
fect -itoken, true after every execution of buy in the original 
model. How to preserve this law while allowing for the new 
transition to a -i/iof-world? 



G^ 



,'-f, -r, -.b) 




' t, -nC, -nh ' 



G^EZ) 



Figure 4: Candidate -ihot-worlds to receive arrows from 
tofen- worlds. 

When pointing a new arrow leaving a world w it is enough 
to preserve old effects only in w (because the remaining 
structure of the model keeps unchanged after adding this 
new arrow). The operation we must carry out is observing 
what is true in w and in the candidate target world w': what 
changes from w to w' (w' \ w) must be what is obliged to 
do so; what does not change from w to w' {w Cl w') must be 
what is either obliged or allowed to do so. 

This means that the only things allowed to change w.r.t. 
w in the candidate target world are those that are forced to 
change: they are relevant to -iip or to another effect that ap- 
plies in w. Every change outside that is not an intended one. 
Similarly, we want the literals preserved in the target world 
to be those that are relevant to -i-ip or to some other effect 
that applies in w or that are usually preserved in w. Every 
preservation outside those may make us lose some law. 

Here is where prime subvaluations play their role: the 
worlds one should aim the new arrow at are those whose 
difference w.r.t. w are literals that are relevant, and whose 
similarity w.r.t. w are literals we know may not change. 

Definition 7 Let ^ = (W,R), w, w' eW, M be such that 
^ G M., and 93 —> \a\'\\) an effect law. Then w' is a relevant 
target world of w w.r.t. ip -^ [a]ip for .M in M. if and only if 

• h ¥'' W,i> 

w w' 

• for all i £ w' \w 

- either there is v G base{-'ip, W) s.t. v Q w' and i £ v 

- or there are i/j' G SttiI, v' G base{ip' , W) s.t. v' C w', 
£ G v', and \= ' [aji/j' for every Mi G M. 

• for all i £ w Hw' 

- either there is v G base{-'ip, W) s.t. v Q w' and i £ v 

- or there are ^' G 5rnl, v' G base(ip' , W) s.t. v' C w\ 
i G v', and \= ' [a]ip' for every Mi G M 

- or there is Mi G M. such that tt ' \a\-^i 

^ w '- -' 

By RelTgt{w, tp -^ [a]V', M , A4)we denote the set of all rel- 
evant target worlds ofw w.r.t. ip —^ [a]ip for M in M.. 



We need the set of models A4 (and here we can suppose 
it contains all models of the theory we want to change) be- 
cause preserving effects depends on what other effects hold 
in the other models that interest us. One needs to take them 
into account in the local operation of changing one modelr 

Definitions Let J( = (W,R) be a PDL-model and M be 
such that ^ G M. Then^' = {W' ,R') G -^ -^mw, if and 
only if 

• W = W 

• RCR' 

• {w,w') e R' \R implies w' e RelTgt{w, ip ^ [a]ip , ^ , M) 

• There is w E W' s.t. l^ w ^r \a}ib 
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[a\ip 



As having just one world where the law is no longer 
true in each model is enough, taking those resulting mod- 
els whose difference w.r.t. the original accessibility relation 
is minimal guarantees minimal change: 

Definition 9 Let ^ be a PDL-model and ip 



effect law. Then 
contraction^^ , ip — > [a]'^) = I J niin{./#^_^r , , , 



a\i}) an 



di^} 



Now we can define the possible sets of models resulting 
from contracting an effect law from a set of models: 

Definition 10 Let M. be a set of models, and (p -^ [a]i/; 
an effect law. Then A^^^[„]^ = {M' : M' = M U 
{.^'},^' e contraction{^ , ip -^ [«](/'), ^ e M}. 

Taking again M = {.'£'}, for ^ as in Figure 2, after 
contracting the effect law token — > [buy\hot from A4, we get 
■^,7j.„^[M'-r = {-^U{^'} : 1 < i < 3}, where all ^/s 
are as depicted in Figure 5. 

If (p is not satisfied by ^ or tp is true in ^, of course we 
do not succeed in falsifying ip — > [a]ip. In these cases, prior 
to do that we must change our set of possible states. 

Contraction of Static Laws 

When contracting a static law in a model, we want to admit 
at least one possible state falsifying it. Intuitively this means 
that we should add new worlds to the original model. This 
is quite easy. A delicate issue however is what to do with 
the accessibility relation: should new arrows leave/arrive at 
the new world? If no arrow leaves the new added world, 
we may lose an executability law. If some arrow leaves it, 
we may lose an effect law, the same holding if we add an 
arrow pointing to the new world. If no arrow arrives at the 
new world, what about the intuition? Do we want to have an 
unreachable state? 

All this discussion shows how drastic a change in the 
static laws may be: it is a change in the underlying struc- 
ture (possible states) of the world! Changing it may have as 
consequence the loss of an effect law or an executability law. 



We do not need A4 in the local contraction of executabilities 




(^t, -^c\ -^iiy* - - -Q, ^c^^/T) (^f, -nc, a) 
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as all effects are preserved along the removal of arrows. 



Figure 5: Models resulting from contracting the effect law 
token -^ [buy]hot in the model ^ of Figure 2. The new 
arrows are the dashed ones. 



What we can do is choose which laws we accept to lose and 
postpone their change (by the other operators). 

The tradition in the reasoning about actions community 
says that executability laws are, in general, more difficult to 
state than effect laws, and hence are more likely to be incor- 
rect. Relying on this, in (Herzig, Perrussel, and Varzinczak 
2006) no change in the accessibility relation is made, what 
means preserving effect laws and postponing correction of 
executability laws. We here embrace this solution. It is con- 
troversial whether this approach is in line with the intuition 
or not (see (Varzinczak 2008a) for an alternative). Anyway, 
with the information we have at hand, this is the safest way 
of contracting static laws. 

Definition 11 Let .# = {W,R) be a PDL-model. Then 

.^' = {W',R') e J(- if and only if 

• R = T^ 

• There is w e W' s.t. ^ ip 

The minimal modifications of one model are as expected: 
Definition 12 Let ./# be a model and ip a static law. Then 

contraction{.y^ , v) = M niin{.^^, i<^} 



And we define the sets of models resulting from contract- 
ing a static law from one set of models: 

Definition 13 Let Ai be a set of models, and ip a static 
law. Then M- = {M' : X' = X U {J('},.£' e 
contraction{.y^ , ip)^.M G M.}. 

In our example, contracting the static law coffee — *• hot 
from A4 = {^}, with .^ as in Figure 2, will give us 



M 



coffee ^>- hot 



= {MU {y^lj, M U {.^#2}}' where each , 



is as depicted in Figure 6. 
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Figure 6: Models resulting from contracting the static law 
coffee — > hot in the model ^ of Figure 2. The new added 
coffee A -i/70?-worlds are dashed. 

Notice that by not modifying the accessibility relation all 
the effect laws are preserved with minimal change. More- 
over, our approach is also intuitive: when learning that a 
new state is now possible, we do not necessarily know all 
the behavior of the action in the new added state. 

Syntactic Operators for Contraction 

We now turn our attention to the definition of a syntacti- 
cal counterpart of our semantic operators. As (Nebel 1989) 
says, "[. . . ] finite bases usually represent [. . . ] laws, and 
when we are forced to change the theory we would like to 
stay as close as possible to the original [. . . ] base." Hence, 
besides the definition of syntactical operators, we should 
also guarantee that they perform minimal change. 

By 7J we denote in the sequel the result of contracting a 
law ^ from the set of laws T. 

Contracting Executability Laws 

For the case of contracting an executability law (/^ — > (a)T 
from an action theory, the first thing we do is to ensure that 
the action a is still executable (if that was so) in all those 



contexts where -k/j is the case. Second, in order to get min- 
imality, we must make a executable in some contexts where 
Lp is true, viz. all (/^-worlds but one. This means that we can 
have several action theories as outcome. 

Algorithm 1 gives a syntactical operator to achieve this. 

Algoritlim 1 Contraction of an executability law 

input: T, Lp ^ {^)~^ 
output: T^^,,^ /* a set of theories */ 
itT^^^ip^{a)Tthen 
for all TT G IP{S A (p) do 
for all A C atm{-n:) do 

if S ^ {-n A Pa) ^ 1. then 



T': 
T- 



{T\ X„) U 

{{pi A-.(7r A vp^)) 



{a)T : p, ^ («)T G X„} 



else 



^^(o>T = 






r 



(°>T 



U{T'} 



As an example, contracting token —> {buy)T from our 
theory Twould give us three theories. One of them is: 

coffee -^ hot, -icoffee — > [buy]coffee, 

token — > [buyj-'token, -^token — > [ZjmjJX, 

-itoken —> [biiyj-itoken, coffee —>■ [buy]coffee, 

hot —> [buy]hot, 

{token A -^coffee A hot) —>■ {buy)T , 

(token A -^coffee A -^hot) — > (buy) T 



^1' = 



Contracting Effect Laws 

When contracting an effect law p —^ [a]ip from a theory T, 
intuitively we should change some effect laws that preclude 
-I'ip in target worlds. In order to cope with minimality, we 
must change only those laws that are relevant to </? ^ [«]'</'■ 
Let £^'^ denote the minimum subset of the effect laws in 
£^ such that 5, Sf'"^ \= p —>■ [a]tp. In the case where the 
theory is modular (Herzig and Varzinczak 2005) (see fur- 
ther), interpolation guarantees that such a set always exists. 
Moreover, note that there can be more than one such a set, 
in which case we denote them {£^''^)i, . . . , i£^''^)n- Let 



£^= U i^a^"^)^ 



l<i<n 

The laws in £^ will serve as guideline to get rid of (^ ^ [a]ijj 
in the theory. 

The first thing that we must do is to ensure that action 
a still has effect tp (if that was so) in all those contexts in 
which p does not hold. This means that we shall weaken the 
laws in £^'^ specializing them to -k/j. 

Second, we need to preserve all old effects in all lyS-worlds 
but one. To achieve that, we specialize the above laws to 
each possible valuation satisfying p but one. In the left p- 
valuation, we must ensure that action a has either its old 
effects or -1-0 as outcome. We achieve that by weakening 
the consequent of the laws in £^ . 



Finally, in order to get minimal change, we must ensure 
that all literals in this (/j-valuation that are not forced to 
change in -i-^-worlds should be preserved. We do this by 
stating an effect law of the form {ipk/\i) — > [a]('0V^), where 
ipk is the above (y9-valuation. The reason why this is needed 
is clear: there can be several -i-i/'-valuations, and as far as we 
want at most one to be reachable from ipk, we should force 
it to be the one whose difference to ipk is minimal. 

Again, the result will be a set of theories. Algorithm 2 
below gives the operator. 

Algorithm 2 Contraction of an effect law 

input: 7^ (yj — > [a]ip 

output: 7^ , , , /* a set of theories */ 

•f^hpDL*^^ HV'then 
for all TT G IP{S A ip) do 

for all A C atm{n) do 



Vi 



A. 



^p. A A, 



if 5 ^plCttAi^a)^ -Lthen 
for all tt' G IP{S A ^^) do 

r':=(T\£„-)U 

{((/p; A -.(tt a i^/t)) -^ [a\i'i : (pi — » [a]'ipi G f,, } U 

{{ipi A TT A ipa) -^ [a](V'i V tt') : ifi -^ [aJV'i G £^} 

for all L C £it do 

if 5 ^pJttA.^,)^ A.eL^and5 ^p^Cvr' A 

A.eL i)^^ then 
for all £ G L do 



ifT^ 
then 



(tt A vpa A ^) ^ [a]^£ or ^ G tt' 



else 

T 



ip^[a]Tl> 



T : = T' \J {{-K ^ LpA h tj -^ [a]{ip\/£)} 
T' n, — 7- ,,, UlT'} 



For instance, contracting the effect law token — > [buy\hot 
from Twill give us three resulting theories, one of them is 
T{ = 

coffee —>■ hot, token —> {buy)T , 

token — > [buy\-itoken, -itoken —> [buy\J-, 

-itoken — i- [buyl-itoken, 

{coffee A -i{token A coffee A hot)) — > [buy]coffee, 

[hot A ->{token A coffee A hot)) — > [buy]hot, 

{^coffee A -i{token A coffee A hot)) — > [buy]coffee, 

{token A coffee A hot) — > [buy]{coffee V -ihot), 

{token A coffee A hot) —> [buy] {hot V -^coffee) 

Contracting Static Laws 

Finally, in order to contract a static law from a theory, we can 
use any standard contraction/revision operator G for classi- 
cal propositional logic to change the set of static laws iS. 
Because contracting static laws means admitting new pos- 
sible states (cf. the semantics), it may be the case that just 
modifying <S is not enough. 

Since we in general do not necessarily know the behav- 
ior of the actions in a new discovered state of the world, a 



careful approach is to change the theory so that all action 
laws remain the same in the contexts where the contracted 
law is the case. In our example, if when contracting the law 
coffee — i- hot we are not sure whether buy is still executable 
or not, we should weaken our executability laws specializ- 
ing them to the context coffee —>■ hot, and then make buy a 
priori inexecutable in all -'{coffee — > hot) contexts. 

Algorithm 3 below formalizes such an operation. 

Algorithm 3 Contraction of a static law 

input: T, ip 

output: T^ I* a set of theories */ 
if S Ixpl"*^ then 

for all 5 £S QifAo 

{{T\s)us-)\x,u 

T':= {{ipiAip)^{a)^■.lp^^{a)^£X,}U 
{-^ ^ [«]±} 

T-: = T-U{T'} 
else 

T-:={'n 



In our running example, contracting the law coffee 
from Tproduces two theories, one of them is 



hot 



^i' = 



-'{-'token A coffee A -'hot), 

{token A coffee — > hot) — > {buy)T, 

-'Coffee -^ [buy]coffee , token —> [buy]-'token, 

-'token -^ [buy]]-, -'token — > [buy]-'token, 

coffee — > [buy]coffee, hot —>■ [buy]hot, 

{coffee A -ihot) —> [buy] _L 



Observe that the effect laws are not affected by the 
change: as far as we do not state executabilities for the new 
world, all the effect laws remain true in it. 

If the knowledge engineer is not happy with the added in- 
executability law (rOj^eeA-i/io?) —> [fewyJ-L, she can contract 
it from the theory using Algorithm 2. 

Correctness of the Operators 

Here we show that our algorithms are correct w.r.t. our se- 
mantics for action theory contraction. Before doing that, we 
need a definition. 

Definition 14 (Modularity (Herzig and Varzinczak 2005)) 

An action theory T is modular if and only if for every 
f e 5ml, i/T|=p|_(/j, then S [=p^ip. 

For an example of a non-modular theory, suppose in our 
action theory T we had stated the law (buy) T instead of 
token —5- {buy)T. Then Tb token and S ^ token. 



In (Herzig and Varzinczak 2005) algorithms are given to 
check whether T satisfies the principle of modularity and 
also to make Tsatisfy it, if that is not the case. 

Theorem 3 T is modular if and only if its big model is a 
model ofT. 



Modular theories have interesting properties. For exam- 
ple, if Tis modular, then its consistency can be checked by 
just checking consistency of the set of static laws S alone. 
Deduction of effect laws does not need the executability 
ones and vice versa. Prediction of an effect of a sequence of 
actions ai; . . . ; a„ does not need the effect laws for actions 
other than ai, . . . ,a„. This also applies to plan validation 
when deciding whether (ai; . . . ; «„)(/? is the case. For more 
results on modularity, see (Herzig and Varzinczak 2007). 

The following theorem (see Appendix A for the proof) 
establishes that the semantic contraction of the law ^ from 
the set of models of the action theory Tproduces models of 
some contracted theory in 7^. 

Theorem 4 Let The modular, and (p be a law. For all M.' G 

M.^ such that \= Tfor every M G M., there is T' E T^ 

such that \= T' for every Jl' ^ M! . 

The next theorem establishes the other way round: models 
of theories in 7J are all models of the semantical contraction 
of <S> from models of T. (The proof is in Appendix B.) 

Theorem 5 Let The modular, (p a law, and T' G T^. For 

all .M' such that |= T , there is M' G A4^ such that 

J(' G M' and |= Tfor every J{, G M. 

Hence our operators are correct w.r.t. the semantics. 

Assessment of Postulates for Change 

We now analyze our operator's behavior w.r.t. Katsuno and 
Mendelzon's classical contraction postulates. (Due to space 
limitations, proofs are omitted here. They are all available 
at (Varzinczak 2008a).) 

Theorem 6 T[=^^T' Jor allT' eT^. 

This result means our operators satisfy the PDL-version of 
Katsuno and Mendelzon's (CI) postulate about monotonic- 
ity. Such a postulate is not satisfied by the operators given 
in (Herzig, Perrussel, and Varzinczak 2006): there, when re- 
moving e.g. an executability law V? ~* ('^}T one may make 
1/3 —s- [a]-L valid in all models of the resulting theory. 

Theorem? IfT^^^^, then [^^^T^ T', for all T' G 7J. 

This corresponds to Katsuno and Mendelzon's (C2) postu- 
late about preservation. Whenever T ^ (p, then the models 
of the resulting theory are exactly the models of T, because 
these are the minimal models falsifying (p. 

Theorem 8 Let T = S U £ U X be consistent, and <!> be 
an executability or an effect law such that S ^ (p. If Tis 

modular, then T' ^ ^ for every T' E T^ 

Thus, under modularity our operators satisfy the success 
postulate (C3). Still under modularity and the assumption 
that the classical contraction operator satisfies Katsuno and 
Mendelzon's (C4) postulate, our operations also satisfy it: 

Theorem 9 Let Ti and T2 be modular If |=„. Ti ^^ 72 

and \= ^1 <-> <l>2, then for each T( G (7i)^^ there is 

T2 G {72)^ such that |= 7^' <-> 7^', and vice-versa. 



Thanks to modularity, our operators also satisfy Katsuno 
and Mendelzon's (C5) postulate, recovery: 

Theorem 10 Let Tbe modular T' U {<P} [=^^ T, for all 

T' eT^. 

Theorem 11 If Tis modular, then every T' G 7J is also 
modular. 

Besides satisfying all postulates for contraction, our opera- 
tors also preserve modularity. This is a nice property, since 
it means that modularity can be checked/ensured once for all 
during the theory's evolution. 

Related Work 

To the best of our knowledge, the first work on updating ac- 
tion theories is that by (Li and Pereira 1996) in a narrative- 
based action description language (Gelfond and Lifschitz 
1993). Contrary to us, however, they investigate the problem 
of updating the narrative with new observed /ac?5 and (pos- 
sibly) with occurrences of actions that explain those facts. 

This amounts to updating a given state/configuration of 
the world (in our terms, what is true in a possible world) and 
focusing on the models of the narrative in which some ac- 
tions took place (in our terms, the models of the action the- 
ory with a particular sequence of action executions). Clearly 
the models of the action laws remain the same. 

(Liberatore 2000) proposes an action language in which 
one can express a given semantics for belief update, like 
(Winslett 1988) and (Katsuno and Mendelzon 1992). Up- 
date operations are then expressed as action laws in a theory. 

The main difference between Liberatore's work and Li 
and Pereira's is that Liberatore's framework allows for ab- 
ductively adding to the action theory new effect propositions 
(effect laws, in our terms) that consistently explain the oc- 
currence of an event. 

The work by (Eiter et al. 2005) is similar to ours in that 
they also propose a framework for updating action laws. 
They mainly investigate the case where e.g. a new effect law 
shall be added to the description. This problem is the dual 
of contraction and is then closer to revision. 

In Eiter etal.'s approach, action theories are also de- 
scribed in a variant of a narrative-based action language. 
Like here, the semantics is in terms of transition systems. 
Contrary to us, the minimality condition on the outcome of 
the update is in terms of inclusion of sets of laws, which 
means the approach is more syntax-oriented than ours. 

Both their framework and ours can be qualified as 
constraint-based update, in that the update is carried out rel- 
ative to a set of laws that one wants to hold in the result. 
Here for example, all changes in the action laws are relative 
to the static laws in S . 

One difference between our approach and Eiter et al.'s is 
that there it is also possible to update a theory relatively to 
e.g. executability laws: when expanding Twith a new effect 
law, one may want to constrain the change so that the action 
under concern is guaranteed to be executable in the result. 
This may of course require the withdrawal of some static 
law. Hence, in Eiter etal.'s framework, static laws do not 
have the same status as in ours. 



Concluding Remarks 

The contributions of the present work are as follows: 

• What is the meaning of removing a law ^ from an action 
theory T? How to get minimal change, i.e., how to keep 
as much knowledge about other laws as possible? We 
answered these questions with Definitions 6, 10 and 13. 

• How to syntactically contract an action theory so that 
its result corresponds to the intended semantics? We 
answered this question with Algorithms 1-3 and Theo- 
rems 4 and 5. 

• Is our method closer to update or revision? Does it 
comply with the standard postulates for classical theory 
change and what are the differences w.r.t. that? We an- 
swered these questions with Theorems 6-11. 

We have shown the importance that modularity has in ac- 
tion theory change. Under modularity, our operators sat- 
isfy all Katsuno and Mendelzon's postulates for contraction. 
This shows that our modularity notion is fruitful. Moreover, 
considering future modifications one should perform on the 
theory, since modularity is preserved by our operators, it suf- 
fices to check/ensure it only once. 

Here we presented the case for contraction. We are cur- 
rently investigating the definition of the revision counterpart 
of action theory change. The first results on this issue are 
available in (Varzinczak 2008b). 

Our ongoing research is on how to contract not only laws 
but any PDL-formula. Definitions 4, 8 and 11 show up to 
be important for better understanding the case of general 
formulas: the modifications to perform in a given model 
in order to falsify a general formula will also comprise re- 
moval/addition of arrows and worlds. The definition of a 
more general contraction method will thus benefit from our 
present constructions. 
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Appendix A: Proof of Theorem 4 

Lemma 1 T[=^J'. 

For the proof of this lemma, the reader is invited to 
check (Varzinczak 2008a). 

Proof of Theorem 4 

Let M = {M ■.\^7}, and M' G M^. We show that 
there is T' £ 7J such that |= T' for every ^' £ M' . 

By definition, each ^' £ A4' is such that either |= Tor 

^^'^. Because T^ ^ 0, there must be T' e 7^. If \^' T, 

by Lemma I |= T' and we are done. Let's then suppose 

that ^ <1>. We analyze each case. 

Let <l> have the form ip — > (a)T for some ip G Jml. Then 
^' = {W',R'), where W' = W, 7?' = /? \ /J^'f, with R'^ = 

{{w, w') :\= Lp and (w, w') G i?a}, for some .^ G M.. 

Let w G W' be such that ^ p ^t (a)T, i.e., 1= o? and 

<(«) = 0. 

Because u W Lp, there must be w G base{p, W') such that 
V C u. Let IT = Afei> ^- Clearly tt is a prime implicant of 
S A ip. Let also ip/^ = A^puVt. ^' ^^d consider 

T' = {7\X^)U{{p,A^{7TAipA)) ^ («>T : ^, ^ («)T G A-J 

(Clearly, T' is a theory produced by Algorithm 1.) 

It is enough to show that .-^' is a model of the new added 
laws. Given [ipi A -'{n A (Pa)) — * ('3')T G T', for every 

w G W', if 1= iv5i A -i(7r A oj/i), then |= (pi, from what it 

follows 1= (y3i. Because \= ipi —>■ {a)T, there is lo' G W 
such that w' G Ra{w). We need to show that {w,w') G 
/?:,. If ^ ^, then R^ = 0, and {w,w') G /?;,. If ^ ip, 
either w = u, and then from 1= n A ip^ we conclude 1= 

u u 

{ipi A -i(7r A ipA)) — > («)T, or m; 7^ w and then we must 
have {w,w') G R'^, otherwise there is S^ C R'^ such that 
R-(R\S'^) C R- (R \ R'^), and then. ^" = {W',R\S^) is 

such that ^ 'Z' — * ('^)T and ^" :<^ ./^' , a contradiction 
because .M' is minimal w.r.t. i<^. Thus (w, w') G /?^' ^^d 

then M^'(a)T. Hence M^'t'. 

w 

Now let ^ be of the form ip —f [a]'0, for iy9, -0 G Jml. 
Then ^' = (W',/?')' where W' = W, R' =R\JR'^'^'^, with 

Rt'""^ = {{w,w') : w G RelTgt{w,ip^ [a]i!,^,M)} 
for some ^ = (W, R) e M. 

Let u G W' be such that p </' — > [«1'0. Then there is 

u 

u' G W' such that {u, u') G ^^ and ^^ ^/;. Because u Ih ip, 

there is ti G base{(p, W') such that w C w, and as u' II up, 

there must be w' G base(-i'4>, W') such that v' C m'. Let 
'r = Aeev^' ^1 = Af6„\„ ^' and tt' = A^e,/ ^- Clearly tt 
(resp. tt') is a prime implicant of iS A 99 (resp. >S A -1^). 



Now let £- = Ui<i<„(^r''^)i and let the theory 

T' = {T\£-)U 

{{ipi A -.(tt a (Pa)) -^ [a]ipi : ipi -^ [ajipi G £7} U 

{{ipi An A pa) ^ [a]{i^i V tt') : pi -^ [a]^^ G S^} U 

{n AipAAi) ^ [a]{i!} V i) : i e L, for L C £it s.t. 

'5^PL(^'AA^eL^)^^. and 

£ e Tv' or T^^^in A ipA A £)^[a]^i 

(Clearly, T' is a theory produced by Algorithm 2.) 

In order to show that ./#' is a model of T', it is enough to 
show that it is a model of the added laws. Given (ipi A-i^n A 

Pa)) -^ [ali^i G T',forevery w G W', if |= piA-i{TrApA), 

1 I -^ 1 1 I -^ T-. I -^ r 1 / I -^ / 

then \= (jji, and then \= p>i. Because \= pi —^ \a\wi, \= Wi 
for all w' £ W such that {w, w') G Rg. We need to show 
that R'^{w) = Ra{w). If ^ p, then TJ^-^'^' = 0, and then 

R'aiw) = Ra{w). If 1= p, then either w = u, and from 

1= TT A (^A we conclude |= (y)i A -'{n A ^Pa)) —^ [aji^i, 
or w ^ u, and then we must have R"^'^^ = 0, otherwise 
there would be Sf'^"^ C Rf'^''' such that R-{R U 5,f '"'^) C 
/?-(/?u;;f'^'^), and then ^" = {W^RUSf^^"^) would be 

such that ^ 'P —* [«]'0 and ./#" ^_^ .^', a contradiction 
since .^' is minimal w.r.t. i<^. Hence R^iw) = Ra{w), 

and 1= ^"1 for all w' such that (w, w') G ^' . 

' t(j' \ ' / K 

Now, given {pi A tt A p>a) ^> [a] (rjji V tt'), for every w G 
W', if 1= piATTA(pA,then\= (/Pi, and then 1= (/Pi. Because, 

w w w 

\= Pi —> [altpi, we have \= ^ ipi for all w' £ W such that 

(w, w') G -/?a, and then |=, ipi for every w' G W' such that 

{w,w') G<\7?^'"'^. Now, given (■«;,«;') G 7?^'"'^, ^'tt', 
and the result follows. 

Now, for each (nAipAAi) — > [a] (-(/'Vi'), for every w G W', 
if 1= TT A Pa A l, then 1= (/?, and then 1= p. Because 

'W w w 

\= (p ^ [a]i!), we have \= ^ ip for every w' G W such that 
(w,w') G /?fl, and then 1= ip for all w' G W' such that 

(«),«;') e R'a\ R"^'""^'. It remains to show that |=, f for 
every w' G W' such that («;,«;') G R'^'"'^ . Since ^' is 
minimal, it is enough to show that 1= i for every £ G £ii 
such that 1= TT A ipA A £. If £ £ tt' , the result follows. 

u 

Otherwise, suppose tfc £. Then 

• either ->£ G tt', then tt' and £ are unsatisfiable, and in this 
case Algorithm 2 has not put the law {tt A (pA A £) —>■ 
[a\{ip V £) in T', a contradiction; 

• or-i^ G w'\w'. In this case, there is a valuation m" = {u'\ 
{^£}) U {£} such that u" 1)/ ip. We must have u" G W', 
otherwise there will be L' = {£i : £i G u"} such that 



T|= (tt' a A^ 6L' ^i) ~* -'-' ^^'^' because Tis modular, 
<S 1= (tt' a Af ei' ^*) ~* -'-' ^'^'^ Ihen Algorithm 2 has 
not put the law {n A ifA A £) — > [a]{i!! V £) in T', a con- 
tradiction. Then u" G W', and moreover u" ^ Rf'^'^{u), 
otherwise ^' is not minimal. As u"\u C w' \ u, the only 
reason why u" ^ R'^'^'^'{u) is that there is ^' G w Pi m" 
such that 1= ' A^ 6u^j ^^ W~'^' for every ^^ G M. 
if and only if I' ^ v' for any v' G base{-''ip, W) such 
that v' C u". Clearly I' = (., and because (. ^ tt', we 

have 1= ' f\t eu^j ~^ [^]~^^ ^^^ every ^i G TM. Then 
T\= {'KAip/i At) —f [a] -i£, and Algorithm 2 has not put 
the law (tt A y)^ A £) — > [a](t/' V £) in T', contradiction. 

Hence we have 1= -0 V £ for every w' G W' such that 

{w,w')eR'„. 

Putting the above results together, we get \= T . 

Let now ^ be some propositional (/3. Then ./#' = 
(W',7?'), where W C W', /?' = R, is minimal w.r.t. ^^, i.e., 
W' is a minimum superset of W such that there is u G W' 
with u \Y ip. Because we have assumed the syntactical clas- 
sical contraction operator is correct w.r.t. its semantics and 
is moreover minimal, then there must be iS^ G 5 (/? such 

that W = val{S-). Hence \^' S- . 

As R' = R, every effect law of Tremains true in ^' . 
Now, let 

{{T\s)us-)\x,u 

r = {{^, A ^) ^ («)T : ^i ^ («)T G XJ U 
{^^ ^ [«]±} 

(Clearly, T' is a theory produced by Algorithm 3.) 

For every {ipi A ip) —> {a)T £ T' and every w G W', if 

1= (fii A ifi, then Ra(w) =/= 0, because \= ipi ^ («)T. Given 

-i(p — > [a]±, for every w G W', if |= -193, then w = u, and 

i?a(M') =0. 

Putting all these results together, we have \= T' . ■ 

Appendix B: Proof of Theorem 5 

Lemma 2 Let <P be a law. If Tis modular, then every T G 
7J is modular. 

Proof: Let <Z> be nonclassical, and suppose there is T' G 7^ 
such that T' is not modular. Then there is some Lp' G Jrnl 
such that T' |= pJ and 5 U; 99', where 5 is the set 
of static laws in T . By Lemma 1, T |= T', and then we 
have T b 1^9'. Because <S> is nonclassical, 5' = S . Thus 
5 U; ip' , and hence Tis not modular. 

Let now ^ be some ip> G i?na[. Then 

((T\5)U<S-)\^„U 
T' = {(v^i A v') ^ (fl)T : ^i -^ (fl)T G XJ U 
{-^ ^ [a]±} 



Suppose Tis modular, and let tp' G S^ml be such that 
T'^^yand5-^py. 

As 5 ^ 99', there is v G va/(5 ) such that v 1)^ p' . 
If V G v'a/(iS), then S ^p.tp', and as Tis modular, T ^_. 
</?'. By Lemma 1, T |= T', and we have T' ^ </?', a 
contradiction. Hence v ^ Vfl/(>S). Moreover, we must have 

V 1)^ ip, otherwise G has not worked as expected. 

Let ^ = {W,R) be such that \^ T' . (We extend ^ 
to another model of T'.) Let ^' = {W',R') be such that 
W' = WU {v} and R' = R. To show that .^' is a model 
of T', it suffices to show that v satisfies every law in T'. 

As V G \'a/(iS^), 1= iS^. Given -k/p ^ [a]± G T', as 

V 1)^ iy9 and R'„{v) = 0, |= -ip> -^ [<2]-L- Now, for every 

(pi — > [a]ipi G T', if 1= Pi, then we trivially have |=^ ijji 

for every v' such that (v, v') G ^^. Finally, given ((/Ji A y)) — s- 
(a)T G T', as v ly- (p, the formula trivially holds in v. Hence 

1= T', and because there is v G W' such that ^ (/?', we 
have T' ^ (/?', a contradiction. Hence for all p' G 5m[ 
such that T' b lyj', 5^ t ip', and then T' is modular. ■ 

For the proof of the following three lemmas, please refer 
to (Varzinczak 2008a). 

Lemma 3 If .4^hig = {Wbig,Rbig) is a model of T, then 

for every .y/^ = {W,R) such that \= T there is a mini- 
mal (w.r.t. set inclusion) extension R' C R^i^ \ R such that 
J(' = {val{S),RUR') is a model of T. 

Lemma 4 Let The modular, and <P be a law. Then T |= ^ 

if and only if every ^' = {val{S),R') such that \= ' T 
and R C R' is a model of4>. 

Lemma 5 Let T be modular, <1> a law, and T' G T^. If 

.^' = {val{S ),R') is a model ofT', then there is M. = 
{M : J( = {val{S),R) and \= 7} such that J(' G M' 
for some M' G M^. 

Proof of Theorem 5 

From the hypothesis that Tis modular and Lemma 2, T' 
is modular. Then ^' = {val{S ),7?) is a model of T', by 
Lemma 4. From this and Lemma 5 the result follows. ■ 



for some S £ S Q p. 



